Stop AI agents from doing the wrong thing

The MCP firewall that intercepts, evaluates, and enforces policy on every AI agent tool call.

EU AI Act compliant · NIS2 ready · 6,330+ tests · <5ms overhead

Quick start docker run -p 3000:3000 ghcr.io/paolovella/vellaveto:latest

What it does

Four pillars of runtime protection for autonomous AI systems.

Intercept

Sits between your AI agent and its tools. Every MCP call passes through Vellaveto before execution.

Evaluate

Policy engine scores each request against configurable rules — scope, sensitivity, blast radius.

Enforce

Allow, deny, or require human approval in real time. No tool call runs without clearance.

Audit

Tamper-evident trail with SHA-256 chains, Merkle proofs, and Ed25519 checkpoints for compliance and forensics.


Regulatory Compliance

Built for the strictest European regulatory frameworks.

EU AI Act
Ready

Art 50 transparency marking, Art 10 data governance, Art 12 record-keeping, Art 14 human oversight.

NIS2
D.Lgs. 138/2024

Incident reporting templates (24h/72h/1M), supply chain security, access control, continuous monitoring.

DORA
Financial

ICT risk management, incident classification, third-party oversight for financial services.

ISO 42001
AI Management

AI management system controls mapped to Vellaveto features.

SOC 2 Type II
Evidence

Automated access review reports, CC6 evidence, trust services criteria mapping.

OWASP Top 10
Agentic 2026

All 10 OWASP Agentic Application risks mitigated: ASI01-ASI10.


Try it

Evaluate a tool call with a single request.

Request
# Evaluate an MCP tool call against your policy
curl -X POST http://localhost:3000/api/evaluate \
  -H "Content-Type: application/json" \
  -d '{
    "tool": "filesystem.write",
    "arguments": {
      "path": "/etc/passwd",
      "content": "..."
    },
    "context": { "agent": "coding-assistant" }
  }'
Response
{
  "decision": "DENY",
  "reason": "write to sensitive system path",
  "policy": "filesystem-protection",
  "risk_score": 0.95,
  "audit_id": "a7f3...c812"
}

Who it's for

Teams running AI agents that interact with real systems through MCP tool access.


By the numbers

6,330+
Tests passing
53
Adversarial audit rounds
<5ms
P99 evaluation latency
20
Formally verified properties

Get started

Explore the source, read the docs, or review the license.